The product does not check for an error after calling a function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference.
Volume of CVEs assigned to CWE-690 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-24409HIGH iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined Behavior and Null Poin | Jan 24, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-24160HIGH NVIDIA TRT-LLM for any platform contains a vulnerability where an attacker could cause an unchecked return value to a null pointer dereference. A successful exploit of this vulner | May 20, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-24411HIGH iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined Behavior in CIccTagXml | Jan 24, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-24410HIGH iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined Behavior and Null Poin | Jan 24, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-24404HIGH iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. In versions 2.3.1.1 and below, CIccXmlArrayType() contains a Nul | Jan 24, 2026 | 8.8 | 28 | NO | NO |
CVE-2020-36646HIGH A vulnerability classified as problematic has been found in MediaArea ZenLib up to 0.4.38. This affects the function Ztring::Date_From_Seconds_1970_Local of the file Source/ZenLib/ | Jan 7, 2023 | 7.5 | 24 | NO | NO |
CVE-2022-22231HIGH An Unchecked Return Value to NULL Pointer Dereference vulnerability in Packet Forwarding Engine (PFE) of Juniper Networks Junos OS allows an unauthenticated, network-based attacker | Oct 18, 2022 | 7.5 | 24 | NO | NO |
CVE-2020-13582HIGH A denial-of-service vulnerability exists in the HTTP Server functionality of Micrium uC-HTTP 3.01.00. A specially crafted HTTP request can lead to denial of service. An attacker ca | Jan 26, 2021 | 7.5 | 23 | NO | NO |
CVE-2026-21689MEDIUM iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versio | Jan 7, 2026 | 6.5 | 22 | NO | NO |
CVE-2024-31165HIGH Unchecked Return Value to NULL Pointer Dereference vulnerability in Open Networking Foundation (ONF) libfluid (libfluid_msg module). This vulnerability is associated with program r | Sep 18, 2024 | 7.5 | 21 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.